L IntegrAuth Lab

← All practicals

P54

Spot a consent-phishing request — before you click Allow

Compose a fake "Microsoft Login" asking for everything, watch the risk banner explain why, then revoke it.

  1. 1

    Load the "Phish" preset: an unverified client requesting files:write + mail:send + offline_access.

    This is the shape of a real consent-phishing attempt — broad write/send access plus PERSISTENT offline_access, from a publisher nobody vouched for.

  2. 2

    Run the assessment and read every fired signal, not just the risk banner.

    Each signal names exactly why it fired — unverified_publisher_sensitive (the central red flag), over_broad, write_or_admin, persistent_access. Never a black box.

  3. 3

    Grant it anyway, then open the connected-apps list below.

    Consent is your call — transparency empowers the decision, it doesn't override it. But the risk you were shown is now a durable record you can review later.

  4. 4

    Revoke the app you just granted.

    Consent hygiene: reviewing and revoking apps you don't recognize (or no longer trust) is the other half of this defense, exactly like the real Connected-apps screen.

Do it

Do the steps above on the lab page, then come back and check your progress.

Open the lab →

🩻 X-ray — what actually happened

Your own insert-only audit trail — the real server events, sanitized (never a secret), each linked to the lesson that explains it.